All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Device Cryptographic Module

Certificate#5056StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorF5, Inc.
Low review priority  ·  no TCB surface named  ·  last validated 10 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/1/2030
CaveatWhen operated in approved mode; When tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and installed as indicated in the Security Policy section 7; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorF5, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Device Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Device Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

F5, Inc. Device Cryptographic Module Last update: August 2025 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware11
Table 3: Modes List and Description11
Table 4: Approved Algorithms14
Table 5: Vendor-Affirmed Algorithms14
Table 6: Non-Approved, Not Allowed Algorithms15
Table 7: Security Function Implementations18
Table 8: Entropy Certificates19
Table 9: Entropy Sources19
Table 10: Ports and Interfaces21
Table 11: Authentication Methods23
Table 12: Roles25
Table 13: Approved Services55
Table 14: Non-Approved Services56
Table 15: Mechanisms and Actions Required60
Table 16: Storage Areas67
Table 17: SSP Input-Output Methods67
Table 18: SSP Zeroization Methods68
Table 19: SSP Table 172
Table 20: SSP Table 275
Table 21: Pre-Operational Self-Tests76
Table 22: Conditional Self-Tests80
Table 23: Pre-Operational Periodic Information80
Table 24: Conditional Periodic Information82
Table 25: Error States83
Figure 1: Block Diagram7
Figure 2 - BIG-IP i4600 and BIG-IP i48008
Figure 3 - BIG-IP i5600, BIG-IP i5800 and BIG-IP i5820-DF8
Figure 4 – BIG-IP i7600, BIG-IP i7800 and BIG-IP i7820-DF8
Figure 5 - BIG-IP i10600, BIG-IP i10800 and BIG-IP i11600-DS, BIG-IP i11800-DS8
Figure 6 – BIG-IP i15600, BIG-IP i15800, BIG-IP i15820-DF8
Figure 7 - B2250 blade mounted in VIPRION chassis C24009
Figure 8 - B4450 blade mounted in VIPRION chassis C44809
Figure 9 - Tamper labels on BIG-IP i4600 and BIG-IP i480061
Figure 10 – Tamper labels on BIG-IP i5600, BIG-IP i5800 and BIG-IP i5820-DF61
Figure 11 – Tamper labels on BIG-IP i7600, BIG-IP i7800 and BIG-IP i7820-DF.62
DS.62
Figure 13 – Tamper labels on BIG-IP i15600, BIG-IP i15800, and BIG-IP i15820-DF.63
Figure 14 – Tamper labels on chassis with VIPRION B2250 blade63
Figure 15 – Tamper labels on chassis with VIPRION B4450 blade64
Page 5

F5®, BIG-IP®, TMOS® are Registered trademarks of F5, Inc. Intel® Xeon® and Intel® Atom® processors are Registered trademarks of Intel Corporation. © 2025 F5, Inc.

Page 6
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy that contains the security rules under which the Device Cryptographic Module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an Overall Security Level 2 module.

1.2 Security Levels

Table 1: Security Levels © 2025 F5, Inc.

Page 7
2 Cryptographic Module Specification
2.1 Description

The Device Cryptographic Module (hereafter referred to as “the module”) is a smart evolution of F5’s market leading Application Delivery Controller (ADC) technology. Solutions built on this platform are load balancers. They are full proxies that give visibility into, and the power to control—inspect and encrypt or decrypt—all the traffic that passes through your network. Purpose and Use: Underlying BIG-IP/ VIPRION hardware and software are F5’s proprietary operating system, Traffic Management Operating System (TMOS), which provides unified intelligence, flexibility, and programmability. With its application control plane architecture, TMOS is a highly optimized system providing control over the acceleration, security, and availability services your applications require. TMOS establishes a virtual, unified pool of highly scalable, resilient, and reusable services that can dynamically adapt to the changing conditions in data centers and virtual and cloud infrastructures. In the following documentation TMOS and BIG-IP are interchangeably used where system and feature modules are concerned. The Control (or Management) Plane refers to the connection from an administrator to the BIG-IP for system management. The Data Plane refers to the traffic passed between external entities and internal servers. Module Type: Hardware Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined by the exterior surface of the appliance (red dotted line in Figure 1). The block diagram below shows the module, its interfaces with the operational environment and the delimitation of its cryptographic boundary. Figure 1 also depicts the flow of status output (SO), control input (CI), data input (DI) and data output (DO). Description of the ports and interfaces can be found in Table- Ports and Interfaces. Figure 1: Block Diagram © 2025 F5, Inc.

Page 8

Tested Operational Environment’s Physical Perimeter (TOEPP): N/ A for hardware module. Diagram, Photograph: Figure 2 - BIG-IP i4600 and BIG-IP i4800 Figure 3 - BIG-IP i5600, BIG-IP i5800 and BIG-IP i5820-DF Figure 4

Page 9
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
i4600 BIG- IP iseriesi460017.1.01Intel® Xeon® D-1518, Broadwell1 x USB port; 8 x 1GbE; 4 x 10GbE network ports; 1 x Console port; 1 x 1GbE management port
i4800 BIG- IP iseriesi480017.1.01Intel® Xeon® D-1518, Broadwell1 x USB port; 8 x 1GbE; 4 x 10GbE network ports; 1 x Console port; 1 x 1GbE management port
i5600 BIG- IP iseriesi560017.1.01Intel® Xeon® E5-1630v4, Broadwell1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port

Figure 7 - B2250 blade mounted in VIPRION chassis C2400 Figure 8 - B4450 blade mounted in VIPRION chassis C4480

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware: © 2025 F5, Inc.

Page 10
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
i5800 BIG- IP iseriesi580017.1.01Intel® Xeon® E5-1630v4, Broadwell1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port
i5820-DF BIG-IP iseriesi5820-DF17.1.01Intel® Xeon® E5-1630v4, Broadwell1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port
i7600 BIG- IP iseriesi760017.1.01Intel® Xeon® E5-1650v4, Broadwel1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port
i7800 BIG- IP iseriesi780017.1.01Intel® Xeon® E5-1650v4, Broadwel1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port
i7820-DF BIG-IP iseriesi7820-DF17.1.01Intel® Xeon® E5-1650v4, Broadwel1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port
i10600 BIG-IP iseriesi1060017.1.01Intel® Xeon® E5-1660v4, Broadwell1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port
i10800 BIG-IP iseriesi1080017.1.01Intel® Xeon® E5-1660v4, Broadwell1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port
i11600-DS BIG-IP iseriesi11600-DS17.1.01Intel® Xeon® E5-2695v4, Broadwell1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE (10/100/1000 capable) management port
i11800-DS BIG-IP iseriesi11800-DS17.1.01Intel® Xeon® E5-2695v4, Broadwell1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE (10/100/1000 capable) management port
i15600 BIG-IP iseriesBIG-IP iseries i1560017.1.01Intel® Xeon® E5-2680v4, Broadwell1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x Console port; 1 x 1GbE management port
i15800 BIG-IP iseriesi1580017.1.01Intel® Xeon® E5-2680v4, Broadwell1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x
Page 11
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures Console port; 1 x 1GbE management port
i15820-DF BIG-IP iseriesi15820-DF17.1.01Intel® Xeon® E5-2680v4, Broadwell1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x Console port; 1 x 1GbE management port
B2250VIPRION C240017.1.01Intel® Xeon® E5-2658v2, Ivy Bridge2 x USB port; 4 x 40 GbE network ports; 1 x Console port; 1 x GbE management port
B4450VIPRION C448017.1.01Intel® Xeon® E5-2658v3, Haswell1 x USB port; 6 x 40 GbE; 2 x 100 GbE network ports; 1 x Console port; 1 x GbE (10/100/1000 Ethernet) management port
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non- Approved modeOnly non-approved security functions can be usedNon- ApprovedEquivalent to the indicator of the requested service as defined in section 4.3

Table 2: Tested Module Identification – Hardware

2.3 Excluded Components
2.4 Modes of Operation

Modes List and Description: Table 3: Modes List and Description The module enters the Approved Mode after the pre-operational self-tests and conditional algorithms self-tests (CASTs) have completed successfully. The module enters the approved mode after pre-operational self-tests succeed. The module automatically switches between the approved and non-approved modes depending on the

2.5 Algorithms
Page 12
AlgorithmCAVP CertPropertiesReference
AES-CBCA3697Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA3698Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CCMA3697Key Length - 128, 192, 256SP 800-38C
AES-CCMA3698Key Length - 128, 256SP 800-38C
AES-CTRA3697Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA3697Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3698Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
Counter DRBGA3697Prediction Resistance - No, Yes Mode - AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
Counter DRBGA3698Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A3697Curve - P-256, P-384 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A3698Curve - P-256, P-384 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3697Curve - P-256, P-384FIPS 186-4
ECDSA KeyVer (FIPS186-4)A3698Curve - P-256, P-384FIPS 186-4
ECDSA SigGen (FIPS186-4)A3697Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A3698Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3697Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3698Component - No Curve - P-256, P-384FIPS 186-4
Page 13
AlgorithmCAVP CertProperties Hash Algorithm - SHA2-256, SHA2-384, SHA2-512Reference
HMAC-SHA-1A3697Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA-1A3698Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-256A3697Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-256A3698Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-384A3697Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-384A3698Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3697Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A3698Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3697Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3698Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SSH (CVL)A3697Cipher - AES-128, AES-256 Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A3697Key Generation Mode - B.3.3 Modulo - 2048, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3697Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A3698Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3697Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
Page 14
AlgorithmCAVP CertPropertiesReference
RSA SigVer (FIPS186-4)A3698Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA3697Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096SP 800-56A Rev. 3
Safe Primes Key GenerationA3698Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096SP 800-56A Rev. 3
Safe Primes Key VerificationA3697Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096SP 800-56A Rev. 3
Safe Primes Key VerificationA3698Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096SP 800-56A Rev. 3
SHA-1A3697Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA-1A3698Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A3697Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A3698Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-384A3697Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-384A3698Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3697Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
TLS v1.2 KDF RFC7627 (CVL)A3698Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)Key Type:AsymmetricN/ARandom bit strings required for generating the cryptographic keys is compliant with [SP 800- 133Rev2] section 4 example 1

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2025 F5, Inc.

Page 15
NameUse and Function
HMAC-SHA2-224, HMAC-SHA2-512Message authentication TLS
Triple-DES, Camellia, SEEDSymmetric encryption and decryption TLS
HMAC-SHA2-256, HMAC-SHA2-512, AES-GCMMessage authentication in IPsec/ IKEv2 protocol
PKCS #1 v1.5 scheme with modulus other than 2048, 3072 or 4096 bits, for all SHA sizesRSA signature generation and verification
PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2-224, SHA2-512; ANS X9.31RSA signature generation
PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512RSA signature verification
ECDSA with curves P-256, P-384 with SHA-1, SHA2- 224, SHA2-512; ECDSA using curves other than P- 256 and P-384, all SHA sizesECDSA signature generation
ECDSA with curves P-256, P-384 with SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P-384, all SHA sizesECDSA signature verification
RSA with modulus sizes up to 16384 bitsRSA encrypt / decrypt
DSA with all key and SHA sizesDSA domain parameter generation, domain parameter verification, key pair generation, signature generation and verification
Diffie-Hellman using MODP1024, MODP2048 groupsShared secret computation in IPsec/IKE protocol
MD5/ SHA-1/ SHA2-224 / SHA2-512Key Derivation function in the context of TLS KDF
EdDSA with Ed25519EdDSA digital signature
SHA-1, AES-ECB, RSA- signature verificationSNMP
TLS ciphersuites implemented by f5-rest-nodeTLS used in SSL Orchestrator (SSLO)
RSA keypair with 2048, 3072 and 4096 (REST API)iControl representation state transfer (REST) access
EC Diffie-Hellman Ephemeral Unified with curves other than P-256, P-384. EC Diffie-Hellman using onePassDH / StaticUnified schemes. Diffie-Hellman using groups other than ffdhe2048, ffdhe3072, ffdhe4096Shared secret computation
Triple-DES, AES-GCM-128, AES-192, AES-256Symmetric encryption and decryption in IPsec /IKEv2
NameTypeDescriptionPropertiesAlgorithms
Key Wrapping/UnwrappingKTS-WrapKey Wrapping,Standard:SP 800- 38F, FIPS 197AES-GCM: (A3698,

Table 6: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations
Page 16
NameTypeDescriptionPropertiesAlgorithms
with authenticated encryptionKey UnwrappingCaveat:Key establishment methodology provides between 128 and 256 bits of security strength IG D.G:approved or allowed methodA3697) AES-CCM: (A3698, A3697)
Key Wrapping/Unwrapping with encryption and authentication in TLSKTS-WrapKey Wrapping, Key Unwrapping in the context of TLSStandard:SP 800- 38F, FIPS 197 Caveat:Key establishment methodology provides between 128, 256 bits of security strength IG D.G:approved or allowed methodAES-CBC: (A3697, A3698) HMAC-SHA2- 256: (A3698, A3697) HMAC-SHA2- 384: (A3698, A3697) HMAC-SHA-1: (A3697, A3698)
Key Wrapping/Unwrapping with encryption and authentication in SSHKTS-WrapFIPS 197, SP 800-38FStandard:SP 800- 38F, FIPS 197 Caveat:Key establishment methodology provides between 128, 256 bits of security strength IG D.G:approved or allowed methodAES-CTR: (A3697) AES-CBC: (A3697) HMAC-SHA-1: (A3697) HMAC-SHA2- 256: (A3697)
Key pair generationAsymKeyPair- KeyGen CKGGenerate an ECDSA, ECDH, DH or RSA key pairECDSA KeyGen (FIPS186-4): (A3698, A3697) RSA KeyGen (FIPS186-4): (A3697) Safe Primes Key Generation: (A3698, A3697) Cryptographic Key Generation (CKG): ()
Page 17
NameTypeDescriptionPropertiesAlgorithms
Key pair verificationAsymKeyPair- KeyVerVerify an ECDSA or ECDH or DH key pairECDSA KeyVer (FIPS186-4): (A3698, A3697) Safe Primes Key Verification: (A3698, A3697)
Signature generationDigSig- SigGenGenerate a digital signatureECDSA SigGen (FIPS186-4): (A3698, A3697) RSA SigGen (FIPS186-4): (A3698, A3697)
Signature verificationDigSig-SigVerVerify a digital signatureECDSA SigVer (FIPS186-4): (A3698, A3697) RSA SigVer (FIPS186-4): (A3698, A3697)
Random Number Generation in Control PlaneDRBGGenerate random bytesCounter DRBG: (A3698)
Random Number Generation in Data PlaneDRBGGenerate random bytesCounter DRBG: (A3697)
Message digestSHACompute a message digestSHA-1: (A3698, A3697) SHA2-256: (A3698, A3697) SHA2-384: (A3698, A3697)
SSH HandshakeKAS-FullKey agreementCaveat:Key establishment methodology provides between 128 and 192 bits of key strength IG D.F:Scenario 2 (path 2)KAS-ECC-SSC Sp800-56Ar3: (A3697) KDF SSH: (A3697)
Page 18
NameTypeDescriptionPropertiesAlgorithms
Key confirmation:no Key derivation:IG 2.4.B SP 800- 135rev1 CVL
TLS Handshake (ECC)KAS-FullKey agreementKey derivation:IG 2.4.B SP 800- 135rev1 CVL IG D.F:Scenario 2 (path 2) Key confirmation:no Caveat:Key establishment methodology provides between 128 and 192 bits of security strengthKAS-ECC-SSC Sp800-56Ar3: (A3698, A3697) TLS v1.2 KDF RFC7627: (A3698, A3697)
TLS Handshake (FFC)KAS-FullKey agreementPrime groups:ffdhe2048, ffdhe3072, ffdhe4096 Caveat:Key establishment methodology provides between 112 to 150-bit Compliance:IG D.F scenario 2 (path 2)TLS v1.2 KDF RFC7627: (A3698, A3697) KAS-FFC-SSC Sp800-56Ar3: (A3698, A3697)

Table 7: Security Function Implementations

2.7 Algorithm Specific Information

AES-GCM: The IV for AES-GCM is constructed in compliance with IG C.H scenario 1a (TLS 1.2). For TLS 1.2, the module offers the AES-GCM implementation and uses the context of Scenario 1a of IG C.H. The module is compliant with SP 800-52r2 section 3.3.1 and the mechanism for IV generation is compliant with RFC5288. The module’s implementation of AES-GCM is compliant to IG C.H option i) where module implements TLS protocol. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. RSA module sizes (IG C.F): All the modulus sizes supported by the module have been ACVP tested for FIPS 186-4 RSA signature verification. SP 800-56Ar3 Assurances: To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the keys for KAS-FFC-SSC and KAS-ECC-SSC must be generated using the © 2025 F5, Inc.

Page 19
CertVendor
NumberName
E74F5
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
CPU Jitter 3.4.0Non- PhysicalOEs listed in Table Tested Module Identification - Hardware256 bitsSHA-3 vetted conditioning component. ACVP Cert. A2621

approved key generation services specified in section 2.9. The module performs full public key validation on the generated public keys. Additionally, the module performs full public key validation on the received public keys. Legacy use (IG C.M): Per SP 800-131r2, the SHA-1 with FIPS 186-4 RSA Digital Signature Verification is used in approved mode (for legacy use). Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-

3 IG C.M.

IG C.K: The module includes CAVP certificates using FIPS 186-4 tests done prior to the IG C.K transition date of Feb 5th, 2024, and are mathematically identical to FIPS 186-5 CAVP tests, hence the module claim FIPS 186-5 compliance for these tests.

2.8 RBG and Entropy

The module employs a Deterministic Random Bit Generator (DRBG) based on [SP 80090Ar1] for the generation of random value used in asymmetric keys, and for providing a RNG service to calling applications. The approved DRBG provided by the module is the CTR_DRBG with AES-256. The output of entropy sources provides 256-bits of entropy to seed and reseed SP 800-90Ar1 DRBG during initialization (seed) and reseeding (reseed). In accordance with FIPS 140-3 IG D.L, the 'Entropy input string', 'seed', 'DRBG internal state (V and key values)' are considered CSPs by the module. No non-DRBG functions or instances are able to access the DRBG internal state.

2.9 Key Generation

The module implements RSA, ECDSA, EC Diffie-Hellman and Diffie-Hellman asymmetric key generation services compliant with [FIPS186-5], using a [SP 800-90Ar1] DRBG. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per [SP 800-133r2] section 4 example 1 (vendor affirmed). The RSA and ECDSA key pairs used for Digital Signature Schemes are generated in accordance with section 5.1 of [SP 800-133r2] and maps specifically to [FIPS 186-5] Appendix A.1.3 (ECDSA) and Appendix A.2.2 (RSA). The ECDH and DH key pairs used for Key Establishment are generated in accordance with section 5.2 of [SP 800-133r2] i.e. key generation method specified in [SP 800-56Ar3]. For this module the applicable method is from [SP 800-56Ar3] section 5.6.1.2 for ECC Key Pair © 2025 F5, Inc.

Page 20

Generation which actually maps to [FIPS 186-5] Appendix A.3.1 and is from [SP 800-56Ar3] section 5.6.1.1 for FFC Key Pair Generation. The module does not implement symmetric key generation as an explicit service. The HMAC and AES symmetric keys are derived from shared secrets by applying [SP 800-135] as part of the TLS/ SSH protocols. The scenario maps to the [SP 800-133r2] section 6.2.1 Symmetric keys generated using Key Agreement Scheme.

2.10 Key Establishment

The module provides the following key establishment services:

128 or 256 bits of encryption strength (AES and HMAC Cert. #A3697).
2.11 Industry Protocols

GCM with internal IV generation in the approved mode is compliant with version 1.2 of the TLS protocol (RFC 5288) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and SSH key derivation functions for use in the TLS protocol and SSH protocol (RFC 4253 and RFC 6668). The TLS 1.2 and SSHv2 protocols have not been reviewed or tested by the CAVP or CMVP. © 2025 F5, Inc.

Page 21
Physical PortLogical Interface(s)Data That Passes
Network Interface (SFP, SFP+, and QSFP+ ports (Ethernet and/or Fiber Optic) which allow transfer speeds from 1Gbps up to 100GbpsData InputTLS/SSH protocol input messages; Configuration commands for interface management
Network Interface (SFP, SFP+, and QSFP+ ports)Data OutputTLS/SSH protocol output messages; Status logs
Network Interface (SFP, SFP+, and QSFP+ ports)Control InputAPI which control system state (e.g. reset system, power-off system)
Network Interface (SFP, SFP+, and QSFP+ ports); Display Interface (LEDs, and/or output to STDOUTStatus OutputAPI which provides system status information
Power InterfacePowerPower Supply (PSU)
3 Cryptographic Module Interfaces

The physical ports mapping to the logical interfaces and the flow of data passing over them are described in the Table below. Table 10: Ports and Interfaces The logical interfaces are the commands through which the users of the module request services. There are no external input or output devices to the module can be used for data The module does not implement Control Output interface. © 2025 F5, Inc.

Page 22
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Role-based authentication with Password (CLI or Web interface)The password must consist of a minimum of 8 characters with at least one from each of the three-character classes. Character classes are defined as: digits (0-9), ASCII lowercase letters (a-z), ASCII uppercase letters (A-Z). - Assuming a worst-case scenario where the password contains six digits, one ASCII lowercase letter and one ASCII uppercase letter. The probability of guessing every character successfully is (1/10)^6 * (1/26)^1 * (1/26)^1 = 1/676,000,000. Note: this is less than 1/1,000,000. - - The maximum number of login attempts is limited to 3 after which the account is locked. This means that, in the worst case, an attacker has the probability of guessing the password in one minute as 3/676,000,000. Note: This is less than 1/100,000.Password1/676,000,0003/676,000,000
Role-based authentication with SSH ECDSA key-pair (CLI only)The ECDSA using P-256 or P-384 curves for key based authentication yields a minimum security-strength of 128 bits . The chance of a random authentication attempt falsely succeeding is at most 1/(2^128) that isECDSA SigVer (FIPS186-4) (A3697)1/(2^128)3/676,000,000
4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 23

Method Name

Description less than 1/1,000,000. - - The maximum number of login attempts is limited to 3 after which the account switch to password authentication. Then the attacker probability of succeeding to establish the connection depends on the probability of guessing the password and it is, as above, 3/676,000,000 less than 1/100,000.

Security Mechanism

Strength Each Attempt

Strength per Minute

NameTypeOperator TypeAuthentication Methods
AdministratorRoleCORole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)

Table 11: Authentication Methods The module supports different roles (one CO role and one User role) which create different authenticated sessions, while achieving the separation between the concurrent operators. Two interfaces can be used to access the module:

4.2 Roles
Page 24
NameTypeOperator TypeAuthentication Methods
AuditorRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
Certificate ManagerRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
ManagerRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
iRule ManagerRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
OperatorRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
Resource ManagerRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
User ManagerRoleUserRole-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)
Page 25
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
List usersDisplay list of all User accountsNoneNoneList of user accountsNoneAdministr ator User Manager Resource Manager Auditor
Create additiona l UserCreate additional UserNoneUsername / passwordConfirmati on of account creationNoneAdministr ator - Password : W User Manager - Password : W
Modify existing UsersModify existing UsersNoneUsernameConfirmati on of account modificati onNoneAdministr ator User Manager
Delete UserDelete UserNoneUsernameConfirmati on of deletionNoneAdministr ator User Manager
Unlock UserRemove lock from user who has exceeded login attemptsNoneUsernameConfirmati on of unlockNoneAdministr ator User Manager

Table 12: Roles At initialization of the module, the CO is the only available role. Only the CO can create the user roles.

4.3 Approved Services

The service indicator gets recorded in the /var/log remote.log file after the service is executed. For approved services, the indicator is identified with the log message 'Service Indicator: Approved' and for non-approved services the log message includes 'Service Indicator: Not Approved'. For SSH service the service indicator is implicit: when the SSH connection is established the service with the cipher selected is approved. :W :W © 2025 F5, Inc.

Page 26
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Update own passwordNoneOwn passwordConfirmati on of update of passwordNoneAdministr ator - Password : W Auditor - Password : W Certificat e Manager - Password : W Manager - Password : W iRule Manager - Password : W Operator - Password : W Resource Manager - Password : W User Manager - Password : W
Update others passwordNoneUsername / passwordConfirmati on of updateNoneAdministr ator - Password : W User Manager - Password : W
Page 27
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Configur e Password PolicySet password policy featuresNoneNew password policyConfirmati on of configurati on changeNoneAdministr ator
Create TLS Certificat eSelf-signed certificate creationService Indicat or: Approv edCertificate identificatio n informationConfirmati on of certificate creationSignature generationAdministr ator - TLS RSA private key: E - TLS ECDSA private key: E Certificat e Manager - TLS RSA private key: E - TLS ECDSA private key: E Resource Manager - TLS RSA private key: E - TLS ECDSA private key: E
Create TLS KeyUsed for the SSL Certificate key fileService Indicat or: Approv edKey identificatio n informationConfirmati on of key creationKey pair generation Random Number Generation in Control Plane Random Number Generation in Data PlaneAdministr ator - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G - DRBG seed : E
Page 28
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
- DRBG internal state (V and key values) : E,W - Entropy input: E Resource Manager - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G - DRBG seed : E - DRBG internal state (V and key values) : E,W - Entropy input: E Certificat e Manager - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G
Page 29
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
- DRBG seed : E - DRBG internal state (V and key values) : E,W - Entropy input: E
Delete TLS Certificat e /KeySelf-signed certificate / key deletionNoneKey identificatio n informationConfirmati on of key / certificate deletionNoneAdministr ator - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z Resource Manager - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z Certificat e Manager - TLS RSA private key: Z - TLS RSA public
Page 30
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z
List Certificat eDisplay / log expiration data of installed certificatesNoneList of certificates to displayCertificate expiration informatio nNoneAdministr ator Auditor Certificat e Manager Resource Manager
List Private KeysList private key information (Name, size)NoneList of private keys to displayTLS private key informatio nNoneAdministr ator Auditor Certificat e Manager Resource Manager
Establish SSH sessionSSH session Key authenticat ion, Key ExchangeSSH connect ion success fulUser / address / password / algorithms / key sizes / key derivationConfirmati on of SSH session authentica tion, Confirmati on of SSH session key exchangeSignature generation Signature verification SSH HandshakeAdministr ator - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH
Page 31
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
derived session key : E Auditor - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Certificat e Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key:
Page 32
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
G,R,W,E - SSH shared secret: G - SSH derived session key : E Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E iRule Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC
Page 33
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Operator - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Resource Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman
Page 34
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E User Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E
Maintain SSH SessionSSH data encryption, decryption, integritySSH connect ion success fulSSH Derived Session keySSH session informatio nKey Wrapping/Unwr apping with encryption and authentication in SSHAdministr ator - SSH derived session key : E
Page 35
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Auditor - SSH derived session key : E Certificat e Manager - SSH derived session key : E Manager - SSH derived session key : E iRule Manager - SSH derived session key : E Operator - SSH derived session key : E Resource Manager - SSH derived session key : E User Manager - SSH derived session key : E
Establish TLS SessionTLS session signature generation and verification , key exchangeService Indicat or: Approv edAddress / algorithms/ keysConfirmati on of digital signature verificatio n of TLS session, Confirmati on of establishmSignature verification Message digest TLS Handshake (ECC) TLS Handshake (FFC)Administr ator - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC
Page 36
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
ent of TLS sessionDiffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Auditor - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman
Page 37
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Certificat e Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret :
Page 38
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
E,G - TLS derived session key : G - TLS primary secret: G Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G iRule Manager - TLS RSA public
Page 39
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Operator - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie-
Page 40
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Resource Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman
Page 41
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G User Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS
Page 42
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
primary secret: G
Maintain TLS SessionTLS data encryption, authenticat ionService Indicat or: Approv edTLS Derived Session keyTLS session informatio nKey Wrapping/Unwr apping with authenticated encryption Key Wrapping/Unwr apping with encryption and authentication in TLSAdministr ator - TLS derived session key : E Auditor - TLS derived session key : E Certificat e Manager - TLS derived session key : E Manager - TLS derived session key : E iRule Manager - TLS derived session key : E Operator - TLS derived session key : E Resource Manager - TLS derived session key : E User Manager - TLS derived session key : E
Page 43
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Delete ssh- keyswapUtility service delete ssh keysNoneSSH key to deleteConfirmati on of SSH key deletionNoneAdministr ator - SSH ECDSA private key: Z - SSH ECDSA public key: Z Resource Manager - SSH ECDSA private key: Z - SSH ECDSA public key: Z
Reboot SystemRestart the cryptograp hic moduleModule rebootsNoneConfirmati on of system rebootNoneAdministr ator - TLS primary secret: Z - TLS derived session key : Z
Secure EraseFull system zeroizationModule end of lifeSelection optionConfirmati on of full system zeroizationNoneAdministr ator - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z - SSH ECDSA public key: Z - SSH
Page 44
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
ECDSA private key: Z - Password : Z
Show versionReturn the HW and FW versions and the module's nameN/AN/AModule name and versionNoneAdministr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager
Show StatusReturn the module statusN/AN/AModule statusNoneAdministr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager
Close TLS / SSH sessionClosing TLS / SSH sessionN/AN/AConfirmati on of TLS/SSH session closureNoneAdministr ator - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS
Page 45
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Auditor - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS
Page 46
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Certificat e Manager - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived
Page 47
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH
Page 48
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z iRule Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z
Page 49
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
- SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Operator - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session
Page 50
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Resource Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC
Page 51
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z User Manager - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC
Page 52
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z
Self-testsExecute integrity test. Execute the CASTsIntegrit y test, CASTs from section 10N/APass or failKey pair generation Key pair verification Signature generation Signature verification Random Number Generation in Control Plane Random Number Generation in Data PlaneAdministr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager
Show licenseReturn license indicationN/AN/AFIPS license informatio nNoneAdministr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager
Import TLS Certificat eImport TLS CertificateNoneCertificate to importConfirmati on of import of certificateNoneAdministr ator - TLS RSA public key: W - TLS
Page 53
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
ECDSA public key: W Certificat e Manager - TLS RSA public key: W - TLS ECDSA public key: W
Export Certificat e FileExport Certificate FileNoneCertificate to exportExported Certificate fileNoneAdministr ator - TLS ECDSA public key: R - TLS RSA public key: R Certificat e Manager - TLS RSA public key: R - TLS ECDSA public key: R
Create ssh- keyswapUtility service create ssh keysService Indicat or: Approv edSSH key to createConfirmati on of SSH key creationKey pair generationAdministr ator - SSH ECDSA private key: G - SSH ECDSA public key: G Resource Manager - SSH ECDSA private key: G - SSH ECDSA
Page 54
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
public key: G
Configur e FirewallSet policy rules, and address lists for use by firewall rulesNonePolicy rules, address listsConfirmati on of policy configurati onNoneAdministr ator
Show firewall stateDisplay the current system- wide state of firewall rulesNoneN/ADisplay the current system wide state of the firewall rules.NoneAdministr ator Manager
Shows statisticsShows statistics of firewall rules on the BIG-IP systemNoneN/AList of statistics of firewall rulesNoneAdministr ator Manager
View System Audit LogDisplay logs/files of configurati on changesNoneN/ADisplay of system audit logsNoneAdministr ator Auditor Resource Manager
Export Analytics Logs SystemExport Analytics Logs SystemNoneN/ADisplay System Analytics LogsNoneAdministr ator Auditor
Enable/ Disable AuditEnable/ Disable AuditNoneN/AConfirmati on of enabling or disabling of auditNoneAdministr ator Resource Manager
Configur e Boot OptionsEnable Quiet boot, Manage boot locationsNoneBoot optionsConfirmati on of configurati on of boot optionsNoneAdministr ator Resource Manager
Configur e SSH access optionsEnable / Disable SSH access, ConfigureNoneSSH access / IP address listConfirmati on of configurati on of SSH access optionsNoneAdministr ator Resource Manager
Page 55
NameDescriptio nIndicat orInputsOutputsSecurity FunctionsSSP Access
IP address allow list
Configur e SSH user configura tionUpdate ssh/ authorized_ keys file for user authenticat ionNonessh/ authorized_ keys fileConfirmati on of configurati on of SSH user configurati onNoneAdministr ator - SSH ECDSA public key: W
Configur e Firewall UsersConfigure Firewall UsersNoneFirewall user and configurati on informationConfirmati on of configurati onNoneAdministr ator
Modify nodes and pool membersEnable / Disable nodes and pool membersNoneWhich nodes and pool members to modifyConfirmati on of modificati on of nodes and pool membersNoneAdministr ator
Configur e nodesCreate, modify, view, delete nodesNoneList of nodes to create / modify / view / deleteConfirmati on of creation / modificati on / display / deletion of nodesNoneAdministr ator Manager Resource Manager
Configur e iRulesCreate, modify, view, delete, iRulesNoneList of iRules to create / modify/ view/ deleteConfirmati on of creation / modificati on / display / deletion of iRulesNoneAdministr ator Manager Resource Manager

Table 13: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP. G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroize: The module zeroizes the SSP. © 2025 F5, Inc.

Page 56
NameDescriptionAlgorithmsRole
Maintain TLS sessionData encryption, Data authenticationHMAC-SHA2-224, HMAC-SHA2-512 Triple-DES, Camellia, SEED DSA with all key and SHA sizesCO / User
SSLO Configuration and usageManagement of the module protected by iApplx authenticationTLS ciphersuites implemented by f5- rest-nodeCO / User
iControl REST accessAccess to the system through REST APIRSA keypair with 2048, 3072 and 4096 (REST API)CO / User
IPsec /IKEv2Protocol configurationHMAC-SHA2-256, HMAC-SHA2-512, AES-GCM Diffie-Hellman using MODP1024, MODP2048 groups Triple-DES, AES-GCM-128, AES-192, AES-256CO / User
Simple network management protocol (SNMP)Protocol configurationSHA-1, AES-ECB, RSA- signature verificationCO / User
Establish TLS sessionSignature generation and verification, Key ExchangePKCS #1 v1.5 scheme with modulus other than 2048, 3072 or 4096 bits, for all SHA sizes PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2-224, SHA2-512; ANS X9.31 PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512 ECDSA with curves P-256, P-384 with SHA-1, SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P- 384, all SHA sizes ECDSA with curves P-256, P-384 with SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P-384, all SHA sizes RSA with modulus sizes up to 16384 bits MD5/ SHA-1/ SHA2-224 / SHA2-512 EdDSA with Ed25519 EC Diffie-Hellman Ephemeral Unified with curves other than P-256, P-384. EC Diffie-Hellman using onePassDH / StaticUnified schemes. Diffie-Hellman using groups other than ffdhe2048, ffdhe3072, ffdhe4096CO / User
4.4 Non-Approved Services

Table 14: Non-Approved Services © 2025 F5, Inc.

Page 57
4.5 External Software/Firmware Loaded
Page 58
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is using the approved integrity technique HMAC-SHA-384. Integrity tests are performed as part of the Pre-Operational Self-Tests. The HMAC key used for integrity check is stored within the module.

5.2 Initiate on Demand

The on demand integrity test is performed as part of the Pre-Operational Self-Tests by powering the module off and powering it on again. © 2025 F5, Inc.

Page 59
6 Operational Environment
6.1 Operational Environment Type and Requirements

The module operates in a non-modifiable operational environment provided by F5 called TMOS 17.1.0.1. The module is a hardware validated at a Security Level 2 in Physical Security. Once the module is operational, it does not allow the loading of any additional firmware. There are no further requirements for this security area. Type of Operational Environment: Non-Modifiable © 2025 F5, Inc.

Page 60
MechanismInspection FrequencyInspection Guidance
Production grade enclosure (SL1)N/AN/A
Opaque enclosure (SL2)N/AN/A
Tamper Evident Labels (SL2)Once per monthThe Crypto Officer/ Administrator is responsible for inspecting the quality of the tamper labels on a regular basis to confirm that the module has not been tampered with. The Crypto Officer/ Administrator checks the quality of the tamper evident labels for any sign of removal, replacement, tearing, etc. If any label is found to be damaged or missing, a kit providing 25 tamper labels is available for purchase.
Hardware Appliance# of Tamper Labels
BIG-IP i4600, BIG-IP i48008
BIG-IP i5600, BIG-IP i5800 BIG-IP i5820-DF7
BIG-IP i7600 BIG-IP i7800 BIG-IP i7820-DF8
BIG-IP i10600 BIG-IP i108007
BIG-IP i11600-DS BIG-IP i11800-DS7
BIG-IP i15600 BIG-IP i15800 BIG-IP i15800-DF7
VIPRION C2400-B22501
VIPRION C4480-B44502
7 Physical Security
7.1 Mechanisms and Actions Required

Table 15: Mechanisms and Actions Required

7.2 User Placed Tamper Seals

Number: Placement: The pictures below show the location of all tamper evident labels for each hardware The tamper labels are delineated with red circles in the pictures below. © 2025 F5, Inc.

Page 61

Figure 9 - Tamper labels on BIG-IP i4600 and BIG-IP i4800 (8 of 8 tamper labels and one opaque screen on second PSU slot) Figure 10 – Tamper labels on BIG-IP i5600, BIG-IP i5800 and BIG-IP i5820-DF (7 / 7 tamper labels and one opaque screen on second PSU slot) © 2025 F5, Inc.

Page 62

Figure 11

Page 63

Figure 13 – Tamper labels on BIG-IP i15600, BIG-IP i15800, and BIG-IP i15820-DF.

1 label on the front, 4 labels on the sides, 2 tamper labels shown circled in orange to mark with

evidence the unauthorized removal of the fan tray and PSUs (replaceable items) that give access to replaceable storage drives. Figure 14 – Tamper labels on chassis with VIPRION B2250 blade (delineated by a red box) and three blanks (1 of 1 tamper label shown and 1/1 opaque screen) © 2025 F5, Inc.

Page 64
Hardware Appliance# of Filler Panels
BIG-IP i4600, BIG-IP i48001 (blank PSU slot)
BIG-IP i5600, BIG-IP i5800 BIG-IP i5820-DF1 (blank PSU slot)
BIG-IP i7600 BIG-IP i7800 BIG-IP i7820-DF0
BIG-IP i10600 BIG-IP i108000
BIG-IP i11600-DS BIG-IP i11800-DS0
BIG-IP i15600 BIG-IP i15800 BIG-IP i15800-DF0

Figure 15

Page 65
Hardware Appliance# of Filler Panels
VIPRION C2400-B22501 (blank blade slot under blade B2250)
VIPRION C4480-B44501 (blank blade slot over blade B4450)
Page 66
8 Non-Invasive Security

Per IG 12.A: Until requirements of SP 800-140F are defined, non-invasive mechanisms fall under ISO / IEC 19790:2012 Section 7.12 Mitigation of other attacks. © 2025 F5, Inc.

Page 67
Storage Area NameDescriptionPersistence Type
RAMThe keys are stored in plaintext form are only accessible to the authenticated operator, to which the SSPs are associatedDynamic
SSD/ HDDThe keys stored in plaintext and the password will remain on the system across power cycle and are only accessible to the authenticated operator to which the SSPs are associatedStatic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
SSPs input during TLS/SSH sessionsUserModuleEncryptedAutomatedElectronic
Public key output during protocol handshakeModuleUserPlaintextAutomatedElectronic
Public key input during protocol handshakeUserModulePlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Secure EraseSingle pass zeroization erasing the HDD or SSD contents and the module itselfAll SSPs present in the module are erased including the one in the non- volatile memoryThe Crypto Officer/ Administrator is calling the Secure Erase service which can only be triggered during reboot of the test platform
Reboot SystemClear the SSPs present in RAM memoryVolatile memory used by the module is overwritten within nanoseconds when the system is reboot.The Crypto Officer/Administrator is calling Reboot System service
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods cryptographic boundary as part of protocol handshake process. Once TLS/SSH session is established any key or data transfer performed thereafter is protected by authenticated encryption provided by the respective protocol

9.3 SSP Zeroization Methods
Page 68
Zeroization MethodDescriptionRationaleOperator Initiation
Delete SSH keyswapDestruction of the selected SSH ECDSA authentication keyZeroization service overwrites the memory occupied by keys with "zeros" or pre-defined values.The Administrator or Resource Manager are calling the Delete SSH keyswap service
Closing TLS/SSH ConnectionZeroization of all session specific keysSSP values generated during key generation services are zeroized by the moduleClosing TLS/SSH Connection
NameDescriptio nSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
TLS RSA private keyRSA private key used for RSA signature generation in TLS protocolModulus N: 2048 and 4096- bits - 112 and 150-bitsAsymmet ric - CSPKey pair generatio nSignatur e generatio n
TLS RSA public keyRSA public key used for RSA signature verification in TLS protocolModulus N: 2048 and 4096- bits - 112 and 150-bitsAsymmet ric - PSPKey pair generatio nSignatur e verificati on
TLS ECDSA private keyECDSA private key used for EC signature generation, shared secret computatio n in TLS protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - CSPKey pair generatio nSignatur e generatio n
TLS ECDSA public keyECDSA public key used for EC signature verification, shared secretCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - PSPKey pair generatio nKey pair verificati on Signatur e verificati on

Table 18: SSP Zeroization Methods

9.4 SSPs
Page 69
NameDescriptio nSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
computatio n in TLS protocol
TLS EC Diffie- Hellma n private keyTLS EC Diffie- Hellman private key used for EC signature generation, shared secret computatio n in TLS protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - CSPKey pair generatio nSignatur e generatio n
TLS EC Diffie- Hellma n public keyEC Diffie- Hellman public key used for signature verification, shared secret computatio n in TLS protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - PSPKey pair generatio nKey pair verificati on Signatur e verificati on
TLS pre- primary secretTLS pre- primary secret used for deriving the TLS primary secretCurve: ECDH: P- 256, P-384 / Curve: DH: ffdhe2048, ffdhe3072, ffdhe4096 - ECDH: 128 and 192-bits / DH: 112, 128, 150- bitsAsymmet ric - CSPTLS Handshake (ECC) TLS Handshake (FFC)TLS Handsha ke (ECC) TLS Handsha ke (FFC)
TLS primary secretTLS primary secret used for deriving the TLS derived key384-bits - 128 or 192-bitsPre- primary secret - CSPTLS Handshake (ECC)TLS Handsha ke (ECC)
TLS derived session keyTLS derived session key from TLS primary secretKey length: 128 and 256- bits (AES); HMAC_SHA1, HMAC-SHA2- 256, HMAC- SHA2-382 - 128 or 192 bitsSymmetri c Key - CSPTLS Handshake (ECC) TLS Handshake (FFC)TLS Handsha ke (ECC) TLS Handsha ke (FFC)
Page 70
NameDescriptio nSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
SSH shared secretSSH shared secret used for deriving the SSH keyCurve: P-256, P- 384 - 128 or 192-bitsSymmetri c Key - CSPSSH HandshakeSSH Handsha ke
SSH derived session keySSH derived session keyKey length: 128 and 256-bits (AES);HMAC_SH A1, HMAC- SHA2-256, - 128 or 192 bitsShared secret - CSPSSH Handshak eSSH Handsha ke
Entropy inputEntropy input string used to seed the DRBG384 bits - 384 bitsRandom number generatio n - CSPRandom Number Generati on in Control Plane Random Number Generati on in Data Plane
DRBG seedDRBG seed derived from entropy input as defined in SP 800- 90Ar1384 bits - 384 bitsRandom number generatio n - CSPRandom Number Generatio n in Control Plane Random Number Generatio n in Data PlaneRandom Number Generati on in Control Plane Random Number Generati on in Data Plane
DRBG internal state (V and key values)Internal state of CTR_DRBG384 bits - 384 bitsRandom number generatio n - CSPRandom Number Generatio n in Control Plane Random Number Generatio n in Data PlaneRandom Number Generati on in Control Plane Random Number Generati on in Data Plane
SSH ECDSAECDSA private key used forCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - CSPKey pair generatio n
Page 71
NameDescriptio nSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
private keykey-based authenticati on in SSH protocol
SSH ECDSA public keyECDSA private key used for key-based authenticati on in SSH protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - PSPKey pair generatio n
SSH EC Diffie- Hellma n private keyEC Diffie- Hellman private key used for key exchange in SSH protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - CSPKey pair generatio nSignatur e generatio n
SSH EC Diffie- Hellma n public keyEC Diffie- Hellman private key used for key exchange in SSH protocolCurve: P-256, P- 384 - 128 and 192-bitsAsymmet ric - PSPKey pair generatio nKey pair verificati on Signatur e verificati on
Passwo rdPassword input by the User or CO during creation of a new user or updating an existing password8 characters - 1/676,000,000Password - CSP
TLS Diffie- Hellma n public keyTLS Diffie- Hellman private key used for EC signature generation, shared secret computatio n in TLS protocolCurve: ffdhe2048, ffdhe3072, ffdhe4096 - 112 to 150-bitsAsymmet ric - PSPKey pair generatio nKey pair verificati on Signatur e verificati on TLS Handsha ke (FFC)
TLS Diffie- Hellma nTLS Diffie- Hellman public key used forCurve: ffdhe2048, ffdhe3072,Asymmet ric - CSPKey pair generatio nSignatur e generatio n
Page 72
NameDescriptio nSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
private keysignature verification, shared secret computatio n in TLS protocolffdhe4096 - 112 to 150-bitsTLS Handsha ke (FFC)
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
TLS RSA private keySSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure EraseRSA public key:Paired With
TLS RSA public keyPublic key input during protocol handshake Public key output during protocol handshakeSSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure EraseRSA private key:Paired With
TLS ECDSA private keySSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure EraseECDSA public key:Paired With
TLS ECDSA public keyPublic key input during protocol handshake Public key output during protocol handshakeSSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure EraseECDSA private key:Paired With
TLS EC Diffie- Hellman private keyRAM:PlaintextFrom handle creation until freeing theReboot System Closing TLS/SSH ConnectionEC Diffie- Hellman public key:Paired With

Table 19: SSP Table 1 © 2025 F5, Inc.

Page 73
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
cipher handle
TLS EC Diffie- Hellman public keyPublic key input during protocol handshake Public key output during protocol handshakeRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionEC Diffie- Hellman private key:Paired With
TLS pre- primary secretRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionTLS primary secret:Used With
TLS primary secretRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionTLS pre-primary secret :Used With
TLS derived session keyRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionTLS primary secret:Derived From
SSH shared secretRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionSSH derived session key :Used With
SSH derived session keyRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH ConnectionSSH shared secret:Derived From
Entropy inputRAM:PlaintextStorage durationReboot SystemDRBG seed :Used With
Page 74
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
during the usage of the CSP
DRBG seedRAM:PlaintextStorage duration during the usage of the CSPReboot SystemDRBG internal state (V and key values) :Used With
DRBG internal state (V and key values)RAM:PlaintextStorage duration during the usage of the CSPReboot SystemDRBG seed :Used With
SSH ECDSA private keySSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure Erase Delete SSH keyswap
SSH ECDSA public keySSPs input during TLS/SSH sessionsSSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleSecure Erase Delete SSH keyswap
SSH EC Diffie- Hellman private keyRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH Connection
SSH EC Diffie- Hellman public keyPublic key output during protocol handshake Public key input during protocol handshakeRAM:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH Connection
PasswordSSPs input during TLS/SSH sessionsSSD/ HDD:PlaintextFrom handle creation until freeing theSecure Erase
Page 75
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
cipher handle
TLS Diffie- Hellman public keyPublic key output during protocol handshake Public key input during protocol handshakeSSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH Connection
TLS Diffie- Hellman private keySSD/ HDD:PlaintextFrom handle creation until freeing the cipher handleReboot System Closing TLS/SSH Connection

Table 20: SSP Table 2 © 2025 F5, Inc.

Page 76
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-384 (A3698)HMAC key: 384-bitsMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity of the module is verified by comparing the HMAC-SHA2-384 value calculated at runtime with the HMAC-SHA2-384 value stored in the module that was computed at build time
HMAC- SHA2-384 (A3697)HMAC key: 384-bitsMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity of the module is verified by comparing the HMAC-SHA2-384 value calculated at runtime with the HMAC-SHA2-384 value stored in the module that was computed at build time
10 Self-Tests

At power-up the module performed the pre-operational self-tests (the integrity test) and the conditional cryptographic algorithm tests (CASTs). Both the pre-operational tests and conditional tests are performed without operator intervention, without any external controls, externally provided test vectors, output results and the determination of pass of fail is done If the module fails any of the tests, the module transitions to the error state and a corresponding error indication is given. The module becomes inoperable, and no services are available. Data output and cryptographic operations are inhibited while the module is in the error State.

10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests The pre-operational self-tests are performed automatically when the module is powered on. Services are not available during the pre-operational self-test and the data output interface is inhibited. On successful completion of the pre-operational self-tests, the module enters operational mode and cryptographic services are available. © 2025 F5, Inc.

Page 77
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A3697)AES-256 in CTR mode, with and without derivation function, prediction resistance disabledKATCASTModule becomes operationalSP 800- 90ARev1 section 11.3 health testsTest runs at power on
AES-CBC (A3698)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest runs at power on
AES-GCM (A3698)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest runs at power on
RSA SigGen (FIPS186-4) (A3698)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature generationTest runs at power on
RSA SigVer (FIPS186-4) (A3698)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature verificationTest runs at power on
RSA KeyGen (FIPS186-4) (A3697)Requested modulus size, SHA2- 256PCTPCTAsymmetric algorithm is performedCalculation and verification of a digital signatureKey generation
ECDSA SigGen (FIPS186-4) (A3698)P-256 and SHA2-256KATCASTModule becomes operationalSignature generationTest runs at power on
ECDSA KeyGen (FIPS186-4) (A3698)Requested curve size, SHA2-256PCTPCTAsymmetric algorithm is performedCalculation and verification of a digital signatureKey generation
KAS-ECC- SSC Sp800- 56Ar3 (A3698)P-256KATCASTModule becomes operationalShared secret computationTest runs at power on
HMAC-SHA-1 (A3697)HMAC-SHA- 1KATCASTModule becomes operationalMACTest runs at power on
HMAC-SHA2- 256 (A3698)HMAC- SHA2-256KATCASTModule becomes operationalMACTest runs at power on
10.2 Conditional Self-Tests
Page 78
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TLS v1.2 KDF RFC7627 (A3698)SHA-256KATCASTModule becomes operationalKey derivation used in the TLS protocolTest runs at power on
KDF SSH (A3697)SHA-256KATCASTModule becomes operationalKey derivation used in the SSH protocolTest runs at power on
HMAC-SHA2- 384 (A3697)HMAC-SHA- 384KATCASTModule becomes operationalMACTest runs at power on
AES-GCM (A3697)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest runs at power on
RSA SigGen (FIPS186-4) (A3697)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature generationTest runs at power on
RSA SigVer (FIPS186-4) (A3697)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature verificationTest runs at power on
KAS-ECC- SSC Sp800- 56Ar3 (A3697)P-256KATCASTModule becomes operationalShared secret computationTest runs at power on
ECDSA SigVer (FIPS186-4) (A3698)P-256 and SHA2-256KATCASTModule becomes operationalSignature verificationTest runs at power on
Safe Primes Key Generation (A3698)Requested curve sizePCTPCTAsymmetric algorithm is performedCalculation and verification of shared secretKey generation
KAS-FFC-SSC Sp800-56Ar3 (A3698)ffdhe2048KATCASTModule becomes operationalShared secret computationTest runs at power on
HMAC-SHA2- 384 (A3698)HMAC-SHA- 384KATCASTModule becomes operationalMACTest runs at power on
Safe Primes Key Generation (A3697)Requested curve sizePCTPCTAsymmetric algorithm is performedCalculation and verification of shared secretKey generation
ECDSA KeyGenRequested curve size, SHA2-256PCTPCTAsymmetric algorithm is performedCalculation and verificationKey generation
Page 79
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
(FIPS186-4) (A3697)of a digital signature
ECDSA SigGen (FIPS186-4) (A3697)P-256 and SHA2-256KATCASTModule becomes operationalSignature generationTest runs at power on
ECDSA SigVer (FIPS186-4) (A3697)P-256 and SHA2-256KATCASTModule becomes operationalSignature verificationTest runs at power on
KAS-FFC-SSC Sp800-56Ar3 (A3697)ffdhe2048KATCASTModule becomes operationalShared secret computationTest runs at power on
HMAC-SHA2- 256 (A3697)HMAC-SHA- 256KATCASTModule becomes operationalMACTest runs at power on
TLS v1.2 KDF RFC7627 (A3697)SHA-256KATCASTModule becomes operationalKey derivation used in the TLS protocolTest runs at power on
HMAC-SHA-1 (A3698)HMAC-SHA- 1KATCASTModule becomes operationalMACTest runs at power on
AES-CBC (A3697)128-bits keyKATCASTModule becomes operationalEncryption/ decryptionTest runs at power on
ESV - Repetition Count Test (Startup)Startup test with 1024 samples; Cutoff value = 90RCTCASTModule is operationalSP 800-90B Heath testPerformed upon startup
ESV - Repetition Count Test (Continuous)Cutoff value = 90RCTCASTModule is operationalSP 800-90B Heath testContinuous test performed for Entropy Source while the module is operating
ESV - Adaptive Proportional Test (Startup)Startup test with 1024 samples; Cutoff value = 459APTCASTModule is operationalSP 800-90B Heath testPerformed upon startup
ESV - Adaptive ProportionalCutoff value = 459APTCASTModule is operationalSP 800-90B Heath testPerformed upon startup
Page 80
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Test (Continuous)
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 384 (A3698)Message AuthenticationSW/FW IntegrityDetermined by the operatorModule is powered-off and on
HMAC-SHA2- 384 (A3697)Message AuthenticationSW/FW IntegrityDetermined by the operatorModule is powered-off and on
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A3697)KATCASTOn DemandManually
AES-CBC (A3698)KATCASTOn DemandManually
AES-GCM (A3698)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3698)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3698)KATCASTOn DemandManually
RSA KeyGen (FIPS186-4) (A3697)PCTPCTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3698)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3698)PCTPCTOn DemandManually

Table 22: Conditional Self-Tests The non-physical entropy source performs the SP 800-90B health test (APT and RCT) classified as CAST:

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information © 2025 F5, Inc.

Page 81
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A3698)KATCASTOn DemandManually
HMAC-SHA-1 (A3697)KATCASTOn DemandManually
HMAC-SHA2- 256 (A3698)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3698)KATCASTOn DemandManually
KDF SSH (A3697)KATCASTOn DemandManually
HMAC-SHA2- 384 (A3697)KATCASTOn DemandManually
AES-GCM (A3697)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3697)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3697)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3697)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3698)KATCASTOn DemandManually
Safe Primes Key Generation (A3698)PCTPCTOn DemandManually
KAS-FFC-SSC Sp800-56Ar3 (A3698)KATCASTOn DemandManually
HMAC-SHA2- 384 (A3698)KATCASTOn DemandManually
Safe Primes Key Generation (A3697)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3697)PCTPCTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3697)KATCASTOn DemandManually
Page 82
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigVer (FIPS186-4) (A3697)KATCASTOn DemandManually
KAS-FFC-SSC Sp800-56Ar3 (A3697)KATCASTOn DemandManually
HMAC-SHA2- 256 (A3697)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3697)KATCASTOn DemandManually
HMAC-SHA-1 (A3698)KATCASTOn DemandManually
AES-CBC (A3697)KATCASTOn DemandManually
ESV - Repetition Count Test (Startup)RCTCASTPrior to entropy generationAutomatically
ESV - Repetition Count Test (Continuous)RCTCASTPrior to entropy generationAutomatically
ESV - Adaptive Proportional Test (Startup)APTCASTPrior to entropy generationAutomatically
ESV - Adaptive Proportional Test (Continuous)APTCASTPrior to entropy generationAutomatically
NameDescriptionConditionsRecovery MethodIndicator
Halt ErrorModule is no longer operational. The data output is inhibited.Integrity test failure Failure of any of the CASTs Failure of any of the PCTs Failure of the APT, RCT at restart (power- on)The module must be re- loadedFor Integrity test failure, CASTs and health tests the module will not load. For PCTs failure the module transitions to error state.
Health Test ErrorModule is no longer operational.Failure of the APT, RCT at runtimeThe module must be re- loadedThe module reboot in a loop

Table 24: Conditional Periodic Information

10.4 Error States
Page 83

Name

Description The data output is inhibited.

Conditions

Recovery Method

Indicator

Table 25: Error States The module must reboot to re-loaded with a fresh image to clear the error condition.

10.5 Operator Initiation of Self-Tests

On demand and periodic self-tests are performed by powering off the module and powering it on again. This service performs the same cryptographic algorithm tests executed during pre-operational self-tests and CASTs. During the execution of the periodic and on-demand self-tests, crypto services are not available and no data output or input is possible. © 2025 F5, Inc.

Page 84
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Startup Procedures: The module is distributed as a part of a BIG-IP product which includes the hardware and an installed copy of firmware with version 17.1.0.1. The hardware devices are shipped directly from the hardware manufacturer/authorized subcontractor via trusted carrier and tracked by that carrier. The hardware is shipped in a sealed box that includes a packing slip with a list of components inside, and with labels outside printed with the product nomenclature, sales order number, and product serial number. Upon receipt of the hardware, the customer is required to perform the following verifications:

Page 85

License Confirmation: The FIPS validated module activation requires installation of the license referred as ‘FIPS license’. The Crypto Officer should call the show license service (with command "tmsh show sys license"), then verify that the list of license flags includes "FIPS 140-3”. Additional Guidance: The Crypto Officer should verify that the following specific configuration rules are followed in order to operate the module in the FIPS validated configuration.

11.2 Administrator Guidance

The Crypto Officer should confirm that version and license are provided according to the documentation in section 11.1. The Crypto Officer should follow the additional guidance in section 11.1 to operate the module in the approved validated configuration. The ESV Public Use Document (PUD) reference for non-physical entropy source is as follows: https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropyvalidations/certificate/74

11.3 Non-Administrator Guidance
11.4 Design and Rules
11.5 End of Life

Secure sanitization of the module consists of using the secure erase service that will perform single pass zero write erasing the disk contents. The service can only be triggered by the administrator during reboot of the device. © 2025 F5, Inc.

Page 86
12 Mitigation of Other Attacks

The module does not implement security mechanisms to mitigate other attacks. © 2025 F5, Inc.

Page 87
Table, extracted as text (did not parse into structured rows)
Appendix A.              Glossary and Abbreviations AES           Advanced Encryption Standard AES-NI        Advanced Encryption Standard New Instructions CAVP          Cryptographic Algorithm Validation Program CBC           Cipher Block Chaining CCM           Counter with Cipher Block Chaining-Message Authentication Code CFB           Cipher Feedback CMAC          Cipher-based Message Authentication Code CMVP          Cryptographic Module Validation Program CSP           Critical Security Parameter CTR           Counter Mode DES           Data Encryption Standard DF            Derivation Function DSA           Digital Signature Algorithm DRBG          Deterministic Random Bit Generator ECB           Electronic Code Book ECC           Elliptic Curve Cryptography ESV           Entropy Source Validation FFC           Finite Field Cryptography FIPS          Federal Information Processing Standards Publication GCM           Galois Counter Mode HMAC          Hash Message Authentication Code KAS           Key Agreement Schema KAT           Known Answer Test KW            AES Key Wrap MAC           Message Authentication Code NDF           No Derivation Function NIST          National Institute of Science and Technology OFB           Output Feedback PAA           Processor Algorithm Acceleration PCT           Pairwise Consistency Test PR            Prediction Resistance PSS           Probabilistic Signature Scheme RNG           Random Number Generator RSA           Rivest, Shamir, Adleman SHA           Secure Hash Algorithm SHS           Secure Hash Standard SSH           Secure Shell TDES          Triple-DES XTS           XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 F5, Inc.
Page 88
Appendix B.References
FIPS140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips- 140-3-ig-announcements
FIPS180-4Secure Hash Standard (SHS) August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-4Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS186-5Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
SP 800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf © 2025 F5, Inc.
Page 89
SP 800-38BNIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 38c.pdf
SP 800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ENIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-38GNIST Special Publication 800-38G - Recommendation for Block Cipher Modes of Operation: Methods for Format - Preserving Encryption March 2016 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38G.pdf
SP 800-56Ar3NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3
SP 800-56Cr2Recommendation for Key Derivation through Extraction-then- Expansion August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2
SP 800-57NIST Special Publication 800-57 Part 1 Revision 4 - Recommendation for Key Management Part 1: General January 2016 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 57pt1r4.pdf
SP 800-67NIST Special Publication 800-67 Revision 1 - Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher January 2012 http://csrc.nist.gov/publications/nistpubs/800-67-Rev1/SP-800-67-Rev1.pdf © 2025 F5, Inc.
Page 90
SP 800-90Ar1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://dx.doi.org/10.6028/NIST.SP.800-90Ar1
SP 800-90BNIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B
SP 800-131r2Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2
SP 800-132NIST Special Publication 800-132 - Recommendation for Password- Based Key Derivation - Part 1: Storage Applications December 2010 http://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2
SP 800-135r1NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 135r1.pdf
SP 800-NIST Special Publication 800-140B - CMVP Security Policy
140Br1Requirements Novembre 2023 https://doi.org/10.6028/NIST.SP.800-140Br1 © 2025 F5, Inc.